CSIDB logo
Threat actor

Phineas Fisher

Attribution profile

Type
Activist
Location
-
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-14 07:11
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Phineas Fisher, also known online as PhineasFisher, is the alias used by an individual or group that has publicly claimed responsibility for leaking internal data from surveillance technology companies. The actor first gained public attention by taking credit for the 2015 Hacking Team data dump and later claimed responsibility for the 2014 leak of internal documents from Gamma Group International. In statements accompanying those leaks, the actor said the motivation was to expose firms that sell surveillance tools to governments known for targeting journalists, dissidents and other civilians in repressive regimes.

The actor’s targeting has focused on companies that develop and sell intrusion and surveillance software, specifically the Italian firm Hacking Team and the UK‑based Gamma Group. Both firms market products such as FinFisher, FinSpy and FinFly ISP to government customers, and the leaked materials showed that those products were being used by authorities in places like Bahrain and Sudan to monitor activists and journalists. This focus on the surveillance‑technology sector reflects the actor’s stated aim of highlighting the role of such firms in enabling state‑sponsored spying.

The tactics observed in the leaks involve the acquisition and public release of large volumes of confidential internal material, including source code, user guides, price lists, internal memos and strategy reports. The disclosed files revealed that the targeted firms incorporated zero‑day exploits sourced from the French company Vupen, which are undisclosed vulnerabilities in widely used software such as Microsoft Office, Internet Explorer and Adobe Acrobat Reader. The documents also showed that the companies were actively working to defeat encryption protections, attempting to bypass tools like Silent Circle, TrueCrypt and Microsoft BitLocker. The actor distributed the stolen data through multi‑gigabyte torrent files, making the material widely accessible to researchers and the public.

Public attribution of the actor to any state sponsor, criminal syndicate or organized hacking group has not been made in the available sources. The individual or collective behind the PhineasFisher persona has remained anonymous, communicating primarily through pseudonymous online accounts and taking credit for the leaks via statements posted on platforms such as Reddit and Twitter. No further details about the actor’s size, structure, financial backing or geographic location have been disclosed in the referenced material.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB